From: James Gray Date: 2009-07-12T08:35:01+09:00 Subject: Re: [ANN] Ruby Versions site; shell access to historical and current Rubies On Jul 11, 2009, at 5:44 PM, David Masover wrote: > On Saturday 11 July 2009 03:02:36 pm James Gray wrote: > >> So, if you steal my password to David's service, you can do what >> exactly? Log into David's service that you were obviously already >> logged into? > > Most people tend to use the same password on multiple services. > > Those who don't should hopefully be smart enough to use ssh keys > instead of passwords for a service like this. Yeah, I feel like we keep discussing security bugs in the users of David's service, not of the service itself. ;) I also feel like you guys felt this service was for heavy work. I felt much more that it was for poking around, satisfying historical curiosities, and trying things out. If you are uploading production code, my opinion is that you've already screwed up. Perhaps David could be persuaded to make the AMI he launched the instance off of publicly available. Then you could just launch your own instance to avoid these security problems. James Edward Gray II